Information Security and Compliance Lead
Paradies LagardèreAbout the role
POSITION DESCRIPTION SUMMARY:
The Information Security & Compliance Lead plays a crucial role in overseeing and driving the organization's information security initiatives and ensuring adherence to regulatory requirements. This position will lead efforts to identify, assess, and mitigate security risks, develop and enforce compliance standards, and foster a culture of security awareness across the organization. This position requires strong leadership skills to lead a team of talented analysts and engineers. In addition to the day-to-day operational needs, this position will also be instrumental in contributing to the development of the overall security and compliance strategy, design, and architecture, aligning with business objectives and strategy.
DUTIES AND RESPONSIBILITIES:
1. Team Leadership and Collaboration:
· Provide guidance to security team members and other stakeholders on security and compliance matters.
· Act as the primary point of contact for cross-functional teams and external stakeholders regarding security and compliance issues.
· Mentor junior team members and foster a collaborative and growth-oriented environment by providing guidance, performance feedback, and fostering a culture of continuous learning and development.
· Foster a results-driven team culture.
· Collaborate with cross-functional teams to align information security and compliance efforts with organizational goals.
· Manage projects on security, privacy, and control initiatives to reduce identified risk to support Information Security, Privacy, Operational Controls and Regulatory compliance strategy.
2. Information Security:
· Lead the annual review and updates of the Company’s information security, privacy and other policies based upon risk of emerging threats, regulations, and best practices which state the Company’s control objectives.
· Lead the team in the design, implementation, and management of security measures to protect organizational data, systems, and networks.
· Conduct risk assessments, vulnerability scans, and penetration tests to identify and mitigate risks.
· Lead incident response efforts, including investigation, resolution, and post-mortem analysis.
· Manage security tools and technologies, including both offensive and defensive solutions.
· Collaborate with IT teams to ensure secure system configurations, applications, and cloud services.
· Stay up to date on emerging threats, vulnerabilities, and industry best practices.
3. Compliance Management:
· Conduct internal audits to ensure adherence to policies and standards.
· Manages Compliance program to meet Company, client and regulatory requirements and reports risk and resolutions to management.
· Develop strong professional relationships with external auditors that will involve coordinating walkthroughs and timing of testing as well as providing the auditors with direct assistance in specific areas.
· Support the Finance, Legal and HR teams with investigations and any other regulatory or compliance needs.
4. Vendor Management:
· Manage relationships with technology vendors and service providers, negotiate contracts, and monitor service level agreements to ensure cost-effective and reliable services.
5. InfoSec / Compliance Innovation:<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s